A comprehensive overview of software assurance methodologies applied to a Public Key Directory project for Fediverse E2EE. The author details their multi-layered testing approach including specification-first development, mutation testing (targeting 90%+ MSI), fuzz testing, static analysis with Psalm/PHPStan/Semgrep,

Table of contents
Cryptography Audits and Other Thought-Terminating ClichésTowards Furry-Grade AssuranceWhat Is Left To DoClosing ThoughtsSort: